North Korean threat actor Jade Sleet has breached an Indian IT services provider, deploying two previously undocumented backdoors in a campaign that targets developers to enable broader supply chain compromise. SentinelOne disclosed the operation on September 21, identifying the new malware families FLATROOF and ROOFDECK as the primary tools used in the attack.
Jade Sleet Compromises Indian IT Services Company Using FLATROOF and ROOFDECK
The breach targeted an unnamed India-based IT services company. Jade Sleet used attack vectors involving Apple-themed lures or Apple platform tools to gain initial access. Once inside the network, the attackers deployed FLATROOF and ROOFDECK, two new backdoor families not previously associated with Jade Sleet operations.
IT service providers represent high-value targets for nation-state actors pursuing supply chain attacks. A foothold in a single IT provider can grant access to dozens or hundreds of client organizations across multiple industries, amplifying the scope and impact of the initial compromise far beyond the breached entity itself.
Why Jade Sleet Targets Developers and IT Infrastructure
Jade Sleet’s focus on developer environments and IT service providers aligns with a broader North Korean strategy of infiltrating software supply chains. Developers often have elevated access to source code repositories, build systems, and production deployment pipelines. Compromising a developer workstation or an IT provider’s infrastructure gives attackers a platform to insert malicious code into software products, push backdoored updates to clients, or exfiltrate proprietary source code.
The use of Apple-themed lures or Apple platform tools suggests Jade Sleet is refining its tactics to target macOS and iOS development environments, which are widely used in software engineering and mobile app development.
FLATROOF and ROOFDECK Capabilities and Deployment
SentinelOne’s disclosure identified FLATROOF and ROOFDECK as new backdoor families deployed in this campaign. While detailed technical specifications were not included in the initial disclosure, both backdoors appear designed for persistent access and lateral movement within compromised networks.
The deployment of two distinct backdoor families in a single operation is consistent with advanced persistent threat tradecraft. Deploying multiple backdoors provides redundancy — if defenders detect and remove one backdoor, the second maintains access. This approach also allows attackers to segment capabilities: one backdoor may handle command-and-control communications while the other focuses on credential harvesting or data exfiltration.
Supply Chain Risk and Downstream Client Exposure
Once Jade Sleet establishes control over an IT service provider, the attackers can pivot to the provider’s client organizations. This pivot can take multiple forms: deploying malicious updates through the provider’s software distribution channels, accessing client networks via the provider’s administrative credentials, or exfiltrating sensitive client data stored on the provider’s infrastructure.
SentinelOne published indicators of compromise and technical details to help organizations detect FLATROOF and ROOFDECK activity. IT service providers and their clients should review access controls for development environments, monitor for the disclosed indicators, and audit recent software updates or administrative actions originating from third-party providers.
Organizations using Indian IT service providers should assess whether their vendor relationships include sufficient visibility into the provider’s security posture and incident response protocols. The breach demonstrates the need for zero-trust architectures that limit the damage a compromised vendor account can inflict on client networks.
Jade Sleet’s Expanding Geographic Targeting
The targeting of an Indian IT services provider represents an expansion of Jade Sleet’s operational focus into South Asia’s technology sector. North Korean APT groups have historically concentrated on financial institutions, cryptocurrency exchanges, and defense contractors, primarily in East Asia and North America. The shift toward India’s IT services industry suggests Jade Sleet is broadening its targeting to regions with significant software development and outsourcing activity.
India’s IT sector serves clients worldwide, making it an attractive entry point for supply chain attacks aimed at organizations in other countries. A successful compromise in India can provide indirect access to networks in North America, Europe, and Asia-Pacific without requiring Jade Sleet to breach those organizations directly.
